diff options
| author | Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr> | 2026-09-24 20:21:05 +0000 |
|---|---|---|
| committer | Jakub Kicinski <kuba@kernel.org> | 2026-09-28 18:21:34 -0700 |
| commit | 512ccd3d0e91e791fb37442aa0a2599aca19783d (patch) | |
| tree | 6bf1e1ab17d74279137877acd0149b2d344ea513 /net/core | |
| parent | fb9b529be016d032860773955a0575908819e7b9 (diff) | |
| download | linux-next-512ccd3d0e91e791fb37442aa0a2599aca19783d.tar.gz linux-next-512ccd3d0e91e791fb37442aa0a2599aca19783d.zip | |
tipc: prevent GCM nonce reuse on peer key changes
TIPC can encrypt traffic between nodes using a different transmit key
for each node. In this mode, the AES-GCM nonce for a packet sent to a
known peer consists of a 32-bit prefix (a per-key salt XOR the peer's
address) followed by a 64-bit counter. That counter is stored in the
peer's RX crypto object. When the peer reports a change in which key
it uses to receive packets, TIPC resets this counter. The sender can
still be using the same TX key and salt, so subsequent packets reuse
earlier nonces. This nonce reuse breaks confidentiality and exposes
GCM's authentication key. This makes forgeries trivial: an attacker
can exploit CTR malleability to alter captured ciphertexts and use the
recovered authentication key to compute a valid tag for the modified
ciphertext, under the same key and nonce.
Use the TX key's existing aead->seqno counter instead. All encryptions
using that key object share the same atomic counter, so concurrent
encryptions get distinct nonce counter values. The counter survives
key activation and peer reconnection, and peer key-status reports
cannot reset it. This prevents those transitions from causing nonce
reuse while the same TX key remains installed.
The nonce format is unchanged, and receivers do not require consecutive
counter values, so sharing the counter across peers remains compatible
with existing receivers. A pre-existing check still invokes key
revocation in the unlikely event that the counter wraps to zero.
Fixes: fc1b6d6de220 ("tipc: introduce TIPC encryption & authentication")
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20260924202105.3722778-1-Jeremy.Jean@oss.cyber.gouv.fr
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Diffstat (limited to 'net/core')
0 files changed, 0 insertions, 0 deletions
